Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Use the packet trace timestamps in netflow records #82

Merged
merged 1 commit into from
Dec 9, 2024

Conversation

Mynacol
Copy link
Collaborator

@Mynacol Mynacol commented Nov 18, 2024

Instead of the current time.
Equally, copy the incoming stream (on the in channel) timestamps.

The aggregate segment will take the first timestamp as flow start and the last timestamp as flow end from all the connected sub-flows for the final flow (at least when the packet trace/flow data is sorted by time).

Instead of the current time.
Equally, copy the incoming stream (on the in channel) timestamps.

The aggregate segment will take the first timestamp as flow start and
the last timestamp as flow end from all the connected sub-flows for the
final flow (at least when the packet trace/flow data is sorted by time).
@Mynacol Mynacol merged commit 278ee12 into BelWue:master Dec 9, 2024
3 checks passed
@Mynacol Mynacol deleted the pcap-timestamps branch December 9, 2024 09:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants